HIGH KEV
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter
Published Sep 11, 2023 ·Due Jun 23, 2025
8.8
HIGHCVSS 3.1
EPSS 39.51%
Description
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.
Affected products
-
- Version 3.0.0.4.386.51598StatusaffectedConstraints-
- Version
AND
- 3.0.0.4.386.51598
-
- Version 3.0.0.4.386.51598StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.md ExploitThird Party Advisory
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.md ExploitThird Party Advisory
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.md ExploitThird Party Advisory
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.md ExploitThird Party Advisory
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.md ExploitThird Party Advisory
- https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.md ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-39780 government-resourceUS Government Resource
- https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/1/EN.md | ExploitThird Party Advisory | |
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/2/EN.md | ExploitThird Party Advisory | |
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/3/EN.md | ExploitThird Party Advisory | |
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/4/EN.md | ExploitThird Party Advisory | |
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/5/EN.md | ExploitThird Party Advisory | |
| https://github.com/D2y6p/CVE/blob/main/asus/CVE-2023-39780/6/EN.md | ExploitThird Party Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-39780 | government-resourceUS Government Resource | |
| https://www.greynoise.io/blog/stealthy-backdoor-campaign-affecting-asus-routers | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 11, 2023
Updated Oct 21, 2025
Reserved Aug 7, 2023
Link CVE-2023-39780
CISA Vulnrichment
Updated Jun 6, 2025